Dashboards & Visualizations

Splunk and variables/constants

ateterine
Path Finder

Rather simple question but not sure if there is a solution for this.

I am running a search

search event_number=123

This search is powering multiple reports. Each report, right now, has that value embedded. Twice a month event_number changes and increases by 1. So when we prepare for the next event, we have to go through all reports and change search strings to

search event_number=124

Was wondering if there is a simple way to set up the variable/constant X=123 and run search
search event_number=X
So when we do change to event_number 125, we would have to do it only once.

Thanks!

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Ayn
Legend

Or eventtypes. Take your pick. 🙂

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...